CVE-2022-40134

CWE-125Out-of-bounds Read5 documents4 sources
Severity
4.4MEDIUM
EPSS
0.1%
top 84.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30
Latest updateJan 31

Description

An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages326 packages

CVEListV5lenovo/biosvarious
NVDlenovo/v520_firmwarem16kt68a
NVDlenovo/v520s_firmwarem16kt68a

🔴Vulnerability Details

2
GHSA
GHSA-p7vc-qcj9-2mj9: An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated2023-01-31
CVEList
CVE-2022-40134: An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated2023-01-30

🕵️Threat Intelligence

1
Qualys
Remediate Your Vulnerable Lenovo Systems with Qualys Custom Assessment and Remediation2022-09-28
CVE-2022-40134 (MEDIUM CVSS 4.4) | An information leak vulnerability i | cvebase.io